Skip to main content

Pre-Requisites for Module 2

Module 2 Prepโฑ 15 min๐Ÿ‘ค All Personas
Pre-Requisites for Module 2

Complete these steps before starting Lab 5. You will access your lab VM, log into the Lab Tenant admin console, and configure the Zscaler Client Connector forwarding profile and Windows app policy. Allow 15 minutes.

Credentials in CloudShare

Open Credentials in your assigned CloudShare environment. For Module 2, use the Zscaler Tenant / Student Admin credentials, not the SDC Credentials used in Module 1.

โšก FINISHED MODULE 1? SET UP THE MODULE 2 ENVIRONMENT HERE

Module 2 (Labs 5โ€“8) runs on the Lab Tenant with a Windows VM and the Zscaler Client Connector. Complete Parts 1โ€“3 below before starting Lab 5.

๐Ÿ“Œ None of this is needed for Module 1 โ€” the Enterprise Tenant login for Labs 1โ€“4 is covered at the start of Lab 1.


Lab Environment Overviewโ€‹

Your lab environment consists of two components:

Lab environment โ€” Corp Client PC connected through Zscaler Zero Trust Exchange to the Internet

ComponentDescription
Corp Client PCA Windows VM in your assigned CloudShare environment. Used for all Kevin (end user) tasks in Labs 6, 7, and 8.
Admin PortalThe Zscaler console accessed from your own laptop. Used for all Alex and Priya tasks.
Zscaler CloudYour traffic and DLP enforcement plane. ZCC on the VM routes all traffic through Zscaler.

Part 1 โ€” Access Your Lab Environmentโ€‹

Step 1 โ€” Locate Your Lab Tenant Credentialsโ€‹

  1. Open your assigned CloudShare environment and select Credentials in the left menu.
  2. Under Zscaler Tenant, locate the Zscaler Admin Console link, Student Admin Username, and One Time Password.
  3. Use these Student Admin credentials for Module 2, not the SDC Credentials listed below them.
CloudShare Credentials panel highlighting the Zscaler Admin Console URL, Student Admin Username, and One Time Password
CloudShare โ†’ Credentials โ†’ Zscaler Tenant. Credential values are masked in this example; use those assigned to your environment.

Step 2 โ€” Access the Lab VMโ€‹

In CloudShare, open the Windows VM tab, shown as Windows 11 x64 in the screenshot. Use VM List to locate the VM if needed.

Verify the VM is ready:

  • Zscaler Client Connector icon visible in the system tray
  • File Dataparity_Q2_2025_Workforce_Financial_Summary.docx is on the Desktop

Step 3 โ€” Log Into the Lab Tenant (Module 2)โ€‹

From your laptop browser, open the Zscaler Admin Console link โ€” console.zscaler.com โ€” and sign in with the Student Admin Username and One Time Password from CloudShare.

If prompted to change the password on first login, set a new password and use it for subsequent admin-console and Client Connector logins.

๐Ÿ’ก Two Tenants โ€” Know the Difference
TenantUsed InAccessLogin URL
Enterprise Tenant (SDC)Modules 1 + 3Read-Onlysdc.zslogin.net
Lab TenantModule 2 onlyRead/Writeconsole.zscaler.com

The facilitator will indicate when to switch tenants at the start of each module.


Part 2 โ€” Configure Zscaler Client Connector (Lab Tenant)โ€‹

These steps configure the Client Connector forwarding profile and app policy on the lab VM. This is required for Labs 6, 7, and 8 to enforce DLP policies on endpoint traffic.

Lab Tenant Required

All steps in Part 2 are performed in the Lab Tenant admin console. Make sure you are using your Lab Tenant credentials before proceeding.

Step 4 โ€” Log Into the Admin Consoleโ€‹

If you are not already logged in from Part 1, go to https://console.zscaler.com from your laptop browser and log in with your Student Admin credentials.

Step 5 โ€” Verify SSL Inspectionโ€‹

  1. In the Lab Tenant admin console, search for ssl.
  2. Select SSL/TLS Inspection Policy under Policies, as shown below.
  3. Confirm that SSL inspection is enabled for the lab traffic. The screenshot shows an Enable SSL rule with Criteria: Any and Action: Inspect. Check that the applicable rule uses Inspect, taking rule order and existing exemptions into account.
Search for SSL/TLS Inspection Policy and verify that the Enable SSL rule has the Inspect action
SSL/TLS Inspection Policy โ€” verify the Inspect action for the lab traffic.
SSL Inspection Required

SSL inspection must be enabled for the lab's HTTPS traffic so that inline DLP can inspect its content. Without it, the traffic will not be inspected as expected and the DLP tests may not produce the expected results. If the inspection rule is missing or not applicable, check with your facilitator before continuing.

Step 6 โ€” Navigate to Forwarding Profilesโ€‹

Click the search bar at the top of the admin console and type forwarding profile (1). Select Forwarding Profile for Platforms from the results (2):

Infrastructure โ†’ Connectors โ†’ Client โ†’ Forwarding Profiles

Search for forwarding profile and select Forwarding Profile for Platforms

Step 7 โ€” Add Forwarding Profileโ€‹

Click Add Forwarding Profile and configure:

  • Profile Name: HandsOnLab_FW_Profile

Add Forwarding Profile โ€” Profile Name HandsOnLab_FW_Profile

Step 8 โ€” Configure Windows Driver and ZIA Tunnel Settingsโ€‹

In the WINDOWS DRIVER SELECTION section, then the FORWARDING PROFILE ACTION FOR ZIA section:

  • Tunnel Driver Type: Packet Filter-Based (1)
  • On-Trusted Network: Tunnel (2)
  • Tunnel version selection: Z-Tunnel 2.0 (3)

Windows driver Packet Filter-Based, ZIA On-Trusted Tunnel, and Z-Tunnel 2.0 selection

Step 9 โ€” Configure VPN, Off-Trusted Network, and ZPAโ€‹

Still in the ZIA section, tick the checkboxes:

  • VPN-Trusted Network: Check Same as "On-Trusted Network" (1)
  • Off-Trusted Network: Check Same as "On-Trusted Network" (2)

Then, in the FORWARDING PROFILE ACTION FOR ZPA section (3):

  • On-Trusted Network: Tunnel
  • VPN-Trusted Network: Same as "On-Trusted Network"
  • Off-Trusted Network: Same as "On-Trusted Network"

Click Save (4).

ZIA VPN and Off-Trusted checkboxes, ZPA forwarding profile section, and Save

Step 10 โ€” Navigate to Windows Platform Settingsโ€‹

Click the search bar and type windows (1). Select Windows (previously part of 'App Profiles') from the results (2):

Infrastructure โ†’ Connectors โ†’ Client โ†’ Platform Settings

Search for windows and select Windows platform settings

Step 11 โ€” Add Windows App Policyโ€‹

Click + Add Windows Policy and configure:

  • Name: HandsOnLab_App_Profile (1)
  • Rule Order: 1 (2)
  • Status: Enabled (3)
  • Forwarding Profile: HandsOnLab_FW_Profile (4)
  • Install Zscaler SSL Certificate: On (5)
  • Notification Template: Legacy Notification Settings (6)
  • User Groups: All Selected (7)

Leave all other settings at their defaults. Don't click Add (8) yet โ€” first complete Step 12 in the same dialog.

Add Windows Policy โ€” name, rule order, status, forwarding profile, SSL certificate, notification template, and user groups

Step 12 โ€” Enable Data Protection / Endpoint DLPโ€‹

Scroll down in the same Add Windows Policy dialog:

  • In the AI & DATA SECURITY section โ€” Install Endpoint ZDP: On (1)
  • Expand NOTIFICATION AND LOGGING (2):
    • Use Zscaler Notification Framework: On (3)
    • Bring Notification to Focus: On (4)

Then click Add to save the policy.

AI & Data Security โ€” Install Endpoint ZDP toggle, and Notification and Logging settings


Part 3 โ€” Setup VM and Login to Zscaler Client Connector (ZCC)โ€‹

Step 1 โ€” Login to the VMโ€‹

Return to the Windows VM tab in your assigned CloudShare environment. If a Windows sign-in is required, use the VM credentials supplied for your environment.

Step 2 โ€” Open and Login to Zscaler Client Connectorโ€‹

Locate the ZCC icon in the system tray (bottom right of the taskbar) โ‘ , right-click it, and select Open Zscaler โ‘ก. The Zscaler Client Connector window opens โ‘ข.

Use your Lab Tenant Student Admin username from Part 1, Step 3 and its current password to log in. If you changed the one-time password, use your updated password here.

ZCC system tray icon, right-click menu, and login screen

Tip โ€” Copy/Paste: If direct paste does not work, use the clipboard controls available in your VM console, or enter the credentials manually.

Step 3 โ€” Verify All Modules Are Activeโ€‹

Once logged in, the ZCC dashboard opens. Confirm the following:

  • Authentication Status: Authenticated (green)
  • Service Status: ON
  • All modules (Private Access, Internet Security, Digital Experience, Data Protection) are visible and active

ZCC dashboard showing all modules active and authentication status Authenticated

Step 4 โ€” Verify Traffic Is Being Steered to Zscalerโ€‹

Open a browser inside the VM and navigate to https://ip.zscaler.com. The page should confirm your traffic is passing through the Zscaler Zero Trust Exchange and display your Zscaler proxy details.

ip.zscaler.com confirming traffic is tunneled through Zscaler Cloud

note

Notepad++ is pre-installed on the VM โ€” no installation needed. It is ready to use for Lab 7.


Quick Reference โ€” All Credentialsโ€‹

WhatURL / AccessUsernamePassword
Enterprise Tenant (Admin)https://sdc.zslogin.net/CloudShare โ†’ Credentials โ†’ SDC Credentials โ†’ Admin UsernamePassword in SDC Credentials
Lab Tenanthttps://console.zscaler.comCloudShare โ†’ Credentials โ†’ Zscaler Tenant โ†’ Student Admin UsernameOne Time Password for initial login; updated password after changing it
Browser DLP Extension (Lab 8)https://enterprise.onsqrx.com/ โ†’ tenant: dlpdemoSDC Admin Username from CloudShareSDC Admin password
Lab VMWindows VM tab in CloudShareVM credentials supplied for your environment, if requestedVM credentials supplied for your environment, if requested
Zscaler Client Connector (VM)N/ASame as Lab Tenant Student Admin usernameCurrent Lab Tenant password
Use Your Assigned Credentials

Tenant identifiers and usernames may differ from the screenshots. Use the credentials in your assigned CloudShare environment.

๐ŸŽ“
Lab Assistant
Zenith Live 2026 ยท Dataparity
Pre-Requisites for Module 2
Browse all topics